EMPCO Legal Compliance 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered a covered entity required to comply with privacy regulations?
- A retail pharmacy that fills prescriptions (Correct answer)
- A law firm that represents hospitals
- A medical device manufacturer
- An IT consulting firm that builds hospital websites
Correct answer: A retail pharmacy that fills prescriptions
Retail pharmacies that transmit health information electronically are covered entities under HIPAA.
Question 2: A pre-employment medical examination may be conducted before a conditional job offer is made under which circumstance?
- When the employer requires all applicants to undergo the same physical exam
- Never — pre-offer medical exams are prohibited by the ADA (Correct answer)
- When the job involves physical labor only
- When the applicant voluntarily requests an examination
Correct answer: Never — pre-offer medical exams are prohibited by the ADA
The ADA prohibits medical examinations before a conditional job offer is made, regardless of the circumstances.
Question 3: Which federal law specifically governs the confidentiality of substance abuse patient records in federally assisted programs?
- HIPAA Privacy Rule
- 42 CFR Part 2 (Correct answer)
- The Rehabilitation Act of 1973
- The Drug-Free Workplace Act
Correct answer: 42 CFR Part 2
42 CFR Part 2 provides stricter confidentiality protections for substance abuse treatment records in federally assisted programs than HIPAA.
Question 4: An employer receives a workers' compensation claim and wants to share the employee's medical records with their insurance carrier. This is:
- Permitted because workers' comp is exempt from HIPAA restrictions (Correct answer)
- Prohibited without explicit written authorization from the employee
- Permitted only if the employee signed a blanket release upon hiring
- Prohibited unless the employer obtains a court order
Correct answer: Permitted because workers' comp is exempt from HIPAA restrictions
Workers' compensation is an exception under HIPAA, allowing disclosure of medical information to workers' comp insurers without individual authorization.
Question 5: The Drug-Free Workplace Act of 1988 applies to which employers?
- All employers with 15 or more employees
- Federal contractors and grantees receiving $100,000 or more (Correct answer)
- All employers engaged in interstate commerce
- Employers in safety-sensitive industries only
Correct answer: Federal contractors and grantees receiving $100,000 or more
The Drug-Free Workplace Act applies to federal contractors awarded contracts of $100,000 or more and federal grant recipients.
Question 6: Under the ADA, an employer's post-offer medical examination must meet which requirement?
- It must be relevant to the specific job functions being offered
- All entering employees in the same job category must be required to take it (Correct answer)
- It may only test for physical conditions, not mental health
- It must be conducted by a physician chosen by the employer
Correct answer: All entering employees in the same job category must be required to take it
Post-offer medical exams are permissible under the ADA only if all entering employees in the same job category are required to take the exam.
Question 7: Which of the following best describes the EMPCO's role in ensuring legal compliance during occupational health screenings?
- Ensuring all medical findings are shared with the requesting employer in full
- Balancing employer fitness-for-duty needs with employee privacy rights and anti-discrimination law (Correct answer)
- Prioritizing production efficiency over medical privacy when conflicts arise
- Deferring all legal determinations to the employer's HR department
Correct answer: Balancing employer fitness-for-duty needs with employee privacy rights and anti-discrimination law
EMPCO professionals must balance legitimate employer needs for fitness-for-duty information with employees' legal privacy rights and protections under ADA, HIPAA, and other laws.
Under HIPAA, which of the following is considered a covered entity required to comply with privacy regulations?